These disclosures remove assumptions that reviewed commit pins, assistant trust origins, and app uninstall were dependable containment boundaries.
The chain is demonstrated; remediation across the four agents remains partial.
Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI plugin or extension installers on developer workstations.
Zero-click execution of repository-controlled plugin code with the coding-agent user's privileges
A repository owner or later compromise can replace reviewed plugin code and obtain zero-click execution with the coding-agent user's privileges.
A SHA-shaped branch can win Git's ambiguous reference resolution, while Gemini CLI has a related FETCH_HEAD path; the agents accepted the materialized checkout without proving that HEAD matched the pin.
OpenAI added an exact post-checkout comparison, and OpenAI and Anthropic published fixed releases, but the cross-agent condition is not fully closed.
The first answer concerns patched SHA-pinned materialization; revocation is not established as part of this fix.
Public exploit code covers five products, while exact fixed versions are missing for some of them.
Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Claude in Chrome on desktop Chromium-based browsers.
Silent browser-agent control, authenticated actions, and—in Chrome or Comet—local-file, screenshot, profile, history, camera, or microphone access
The extension does not merely alter a page: it impersonates an assistant's trusted front end and inherits authority over authenticated browser actions and, in some products, local data and sensors.
The starting point is an installed Chromium extension with broad host and declarative-network permissions; Edge and Claude additionally require debugger permission.
Request rewriting, content scripts, privileged-origin mistakes, and an Edge state race let the extension issue commands without a real user gesture.
Demonstrated outcomes include authenticated actions and, in Chrome or Comet, access to files, screenshots, profile data, history, camera, or microphone.
The victim must install the APK and approve Accessibility; the published analysis identifies no patch.
Android phones on which a victim sideloads the RatHat dropper and grants Accessibility; the research does not publish a complete tested OS or OEM range.
Shell-level persistence outside the app lifecycle, automatic reinstallation, and lock-credential capture from raw input
Persistence moves outside the package lifecycle, so removing the app no longer removes its shell foothold.
Accessibility turns on Wireless Debugging, reads the pairing data, and pairs an embedded client with localhost adbd as shell UID 2000.
Agents staged under /data/local/tmp remain after package removal and can reinstall the APK with its permissions and Accessibility restored.
The shell can also read raw input coordinates and map them to PIN or pattern layouts.
Cisco Secure Email Gateway, physical and virtual email-security appliances running Cisco AsyncOS.
A crafted message delivered to an affected physical, virtual, or Cisco-hosted gateway is parsed without authentication or recipient interaction; malicious SQL reaches operating-system command execution as root.
Cisco publishes fixed release boundaries, and post-exploitation access can include cluster SSH keys or removal of local evidence.
LiteSpeed Web Server Enterprise, the commercial web server commonly deployed on shared cPanel, Plesk and DirectAdmin Linux hosts.
The path starts from a low-privilege hosting account and reaches the privileged lscgid helper; incident response confirmed root access and webshells in other tenants' accounts.
The exact request sequence is not public, and although fixed builds exist, pre-fix server images remain accepted.
Apple iOS and iPadOS, the operating systems on supported iPhones and iPads.
The attacker needs both possession and an existing trust pairing; a path traversal then escapes the backup path and reaches arbitrary files.
Apple shipped fixed releases, but pre-fix images remain accepted and revocation is incomplete.
Docker VMM, the macOS virtual-machine backend used by Docker Sandboxes and optionally by Docker Desktop.
By unlinking an open workspace file and replacing its parent with a symlink, guest code makes virtio-fs reopen the saved pathname outside the authorized workspace.
The result is host-user file read or overwrite, with code execution available through writable startup or configuration files; a three-line reproducer is public.
Docker Desktop 4.88.0 contains the fix.
Unbound, a validating recursive DNS resolver deployed on servers and network appliances.
A crafted DNSKEY makes digest processing decompress attacker-controlled data beyond its heap buffer when a vulnerable validating resolver queries the attacker's zone.
Code execution is possible but has not been publicly demonstrated; Unbound 1.26.1 contains the fix.
Linux kernel netfilter bridge ebtables SNAT handling on systems with the vulnerable code and applicable ARP rewrite rules.
Namespace-local CAP_NET_ADMIN and an ARP-rewriting ebtables SNAT rule are required; ebt_snat then writes an attacker-chosen MAC address into a shared backing page without first making the fragment writable.
A patch exists, but public evidence does not identify the corrupted target or whether exploitation ends in host root, container escape, persistence, or another result.
Red Hat OpenShift Container Platform console, the web management interface deployed with OpenShift Kubernetes clusters.
A caller reaching the public devfile endpoints can make the console pod request an attacker-selected internal URL and receive part of its response.
The same parser can exhaust console memory with requests lacking a declared content length, and the accessible record does not identify exact fixed builds.
Discourse forums that process HEIF uploads with vulnerable libheif builds, when connected to OpenAI SSO services.
A low-privilege Discourse user could upload a crafted HEIF image, turn a libheif overflow into server-side execution, and compose that compromise with an OpenAI SSO trust-boundary flaw.
The demonstrated no-interaction transition took over an active account and used an employee's Codex connection to open an internal-repository pull request.
Discourse publishes patched releases for the image-processing flaw.
The published fix was not read for this brief, so this cannot lead.
CUPS and cups-filters, the printing service and backend collection used on Ubuntu and other Linux/Unix systems.
A local lpadmin member can use the privileged serial backend to rewrite cups-files.conf, crash cupsd, and have systemd restart it with an attacker-controlled ServerBin path.
The restarted daemon executes a replacement cups-exec as root without leaving the CUPS AppArmor profile.
Public exploit code exists, the root shell was independently reproduced, and no upstream patch is identified.
Argo Workflows, a Kubernetes-native workflow orchestration control plane commonly used for CI, data processing and deployment automation.
The metadata.namespace!= selector passes authorization against the supplied namespace value but becomes a SQL inequality returning other tenants' records.
Those records can expose workflow definitions, parameters, annotations, environment hints, and error traces; patched version ranges are published.
The published fix was not read for this brief, so this cannot lead.
CareCam HMT.CM2507, an embedded IP security camera.
The live-video service performs no authentication, while a privileged ONVIF account accepts an empty password.
No fixed release is identified in the cited coordination record.
TOTOLINK A3002MU, an embedded AC1200 home router running a MIPS Boa management service.
An unauthenticated formFilter request sends an up-to-4096-byte URL into a 36-byte stack buffer, overwriting the saved MIPS return address at offset 656.
The trigger is public, but arbitrary command execution on stock hardware has not been demonstrated.
Apple iOS and iPadOS, the operating systems on supported iPhones and iPads.
Attacker-controlled app code submits paths to MobileBackup; insufficient validation carries those paths into protected file-system locations.
Updating closes the documented path on fixed releases, but the continued acceptance of pre-fix images leaves rollback and fleet-completeness questions unresolved.
No additional findings today.
No new Secure Boot bypass, disk-encryption defeat, measured-boot forgery, or boot-stage privilege transition was established.
Recent BlueZ and device material added crash paths, identifiers, or fixes without making the attacker position cheaper.
The D-Link R95 administrator-to-root path had working code but did not move a meaningful device trust boundary.
No new unlock or disk-encryption bypass was established; the MobileBackup physical path still requires an existing trust pairing.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.